OWASP Q1 report highlights excessive agency as an exploited risk
Open
OWASP’s Q1 2026 exploit round-up identifies LLM06:2025 Excessive Agency among the Top 10 LLM risks exploited in reported activity.[1] Excessive agency concerns systems that allow models or agents to take actions beyond intended human or policy boundaries.[1]
Why it matters
Security teams should constrain tool permissions, require authorization gates, and monitor agent actions rather than treating model output as harmless text.
OWASP GenAI Security Project
Agentic systems expand the prompt-injection attack surface
Open
OWASP’s agentic-security guidance highlights agent behavior hijacking, tool misuse and exploitation, and identity and privilege abuse as key threats.[7] Microsoft’s overview similarly describes risks from untrusted content, chained tools, delegated identities, and persistent sessions.[11]
Why it matters
Agent deployments need session-level controls, least-privilege identities, trusted tool boundaries, and defenses against instructions embedded in retrieved or external content.
OWASP GenAI Security Project